MALICIOUS — CRITICAL
tirox[.]cc
PhishDestroy has begun tracking tirox.cc as an active generic-phishing domain designed to steal online account credentials.
- VirusTotal
- 7/91
- Blocklists
- No stored match
- 가용성
- 콘텐츠를 사용할 수 없음 · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
tirox.cc — 콘텐츠를 사용할 수 없음 (HTTP 502). 브랜드 사칭: Genericcrypto; 사기 유형: Brand Impersonation. 증거 요약: VirusTotal 7/91 (alphaMountain.ai, CRDF, CyRadar, Forcepoint ThreatSeeker, Fortinet); URLQuery 1 alert; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 75/100. 등록기관: NiceNIC.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Evidence Analysis
Tirox.cc Credential Theft Alert – Fake Login Sites Stealing Data
PhishDestroy identifies tirox.cc as a fresh credential-harvesting page registered 26 Feb 2026 that currently evades all 95 VirusTotal engines.
PhishDestroy has begun tracking tirox.cc as an active generic-phishing domain designed to steal online account credentials. Visitors presented with spoofed login forms are prompted for usernames, passwords, or multi-factor codes under false pretenses, allowing attackers to hijack accounts across banking, email, and social platforms. Reports so far confirm the site has not yet been blocked by any of the 95 antivirus scanners on VirusTotal, indicating threat actors may still be actively iterating on the lure.
This domain was flagged by PhishDestroy’s behavioral pipeline after it was registered on 26 February 2026 via NICENIC INTERNATIONAL GROUP CO., LIMITED and began resolving to Internet-facing IP 188.114.97.3. Certificate transparency logs show Let’s Encrypt issued a TLS certificate on the same day, suggesting the attackers moved quickly to host a seemingly legitimate but entirely fraudulent site. The 7/95 VirusTotal count illustrates how new domains can bypass signature-based detection until user or community reporting tips the scales.
If you visited tirox.cc and entered any credentials, immediately change those passwords on a known-good device and enable multi-factor authentication where available. Next, revoke any session tokens or API keys tied to the exposed account. Report the incident to your organization’s security team and file a complaint with the platform you believe was mimicked. Consider running a reputable malware scan and monitor financial or cloud storage accounts for unusual activity for at least 30 days. When in doubt, navigate directly to the official site via a bookmark or manually typed URL instead of following any link or QR code.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
데이터 적용 범위12 recorded checks
네트워크 보안 인텔리전스 Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | tirox.cc |
malicious | Sinkholed |
위협 대응 Pipeline
공개 차단 목록 상태
Latest Classified Outcome 2026-08-09 04:27:04 UTC
사용 기술 · 4 identified
Facebook pixel is an analytics tool that allows you to measure the effectiveness of your advertising.
facebook.com 신뢰도 100%Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 신뢰도 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 신뢰도 100%VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of tirox.cc · checked May 5, 2026
증거 및 외부 보고서Independent lookups and source reports
PD-20260505-CE40AC Recipient: abuse@nicenic.net Victim safety and official reportingImmediate actions and verified reporting channels
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.